From 6fa587f55ea8599ad80039be503f1908d8aee5b2 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 9 Feb 2026 09:23:32 +0000 Subject: [PATCH 1/2] Initial plan From 66be730cc8bf8d6b738032a3bd56979893153b78 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 9 Feb 2026 09:29:31 +0000 Subject: [PATCH 2/2] Add advanced auth endpoints to public routes and tests Co-authored-by: cadtoolbox <12723486+cadtoolbox@users.noreply.github.com> --- backend/app/main.py | 2 ++ backend/tests/integration/test_auth_api.py | 27 ++++++++++++++++++++++ 2 files changed, 29 insertions(+) diff --git a/backend/app/main.py b/backend/app/main.py index ff50cd81e..1be272f19 100644 --- a/backend/app/main.py +++ b/backend/app/main.py @@ -2636,6 +2636,8 @@ PUBLIC_API_ROUTES = { "/api/v1/auth/status", "/api/v1/auth/login", "/api/v1/auth/setup", # Needed for initial setup and recovery + "/api/v1/auth/advanced-auth/status", # Advanced auth status needed for login page + "/api/v1/auth/forgot-password", # Password reset for advanced auth # Version check for updates (no sensitive data) "/api/v1/updates/version", # Metrics endpoint handles its own prometheus_token authentication diff --git a/backend/tests/integration/test_auth_api.py b/backend/tests/integration/test_auth_api.py index 90cbf192a..ba1bfa4b4 100644 --- a/backend/tests/integration/test_auth_api.py +++ b/backend/tests/integration/test_auth_api.py @@ -774,3 +774,30 @@ class TestAuthMiddlewarePublicRoutes: headers={"Authorization": f"Bearer {token}"}, ) assert response.status_code == 200 + + @pytest.mark.asyncio + @pytest.mark.integration + async def test_advanced_auth_status_is_public(self, async_client: AsyncClient, enabled_auth): + """Verify /api/v1/auth/advanced-auth/status is accessible without auth.""" + response = await async_client.get("/api/v1/auth/advanced-auth/status") + # Should not be 401 (must be accessible for login page) + assert response.status_code != 401 + # Should return valid response (200 with auth status) + if response.status_code == 200: + result = response.json() + assert "advanced_auth_enabled" in result + assert "smtp_configured" in result + + @pytest.mark.asyncio + @pytest.mark.integration + async def test_forgot_password_is_public(self, async_client: AsyncClient, enabled_auth): + """Verify /api/v1/auth/forgot-password is accessible without auth.""" + response = await async_client.post( + "/api/v1/auth/forgot-password", + json={"email": "test@example.com"}, + ) + # Should not be 401 (must be accessible for password reset from login page) + assert response.status_code != 401 + # Will likely be 400 (advanced auth not enabled) but that's okay - + # the important thing is it's not blocked by auth middleware + assert response.status_code in [200, 400]